{"id":13625903,"url":"https://github.com/sirwart/ripsecrets","last_synced_at":"2025-10-21T04:53:45.607Z","repository":{"id":39892452,"uuid":"482145892","full_name":"sirwart/ripsecrets","owner":"sirwart","description":"A command-line tool to prevent committing secret keys into your source code","archived":false,"fork":false,"pushed_at":"2025-09-15T23:35:59.000Z","size":215,"stargazers_count":868,"open_issues_count":15,"forks_count":28,"subscribers_count":8,"default_branch":"main","last_synced_at":"2025-10-02T06:53:14.806Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/sirwart.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2022-04-16T03:34:10.000Z","updated_at":"2025-09-27T21:08:48.000Z","dependencies_parsed_at":"2024-01-16T01:53:39.294Z","dependency_job_id":"ee86b866-dcb7-4f29-89e6-65b00ad9a788","html_url":"https://github.com/sirwart/ripsecrets","commit_stats":{"total_commits":59,"total_committers":8,"mean_commits":7.375,"dds":0.576271186440678,"last_synced_commit":"cba144e474490358e8b2e3134d16e00abd10e0e4"},"previous_names":["sirwart/secrets"],"tags_count":12,"template":false,"template_full_name":null,"purl":"pkg:github/sirwart/ripsecrets","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sirwart%2Fripsecrets","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sirwart%2Fripsecrets/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sirwart%2Fripsecrets/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sirwart%2Fripsecrets/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sirwart","download_url":"https://codeload.github.com/sirwart/ripsecrets/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sirwart%2Fripsecrets/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":280207194,"owners_count":26290616,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-21T02:00:06.614Z","response_time":58,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T21:02:05.105Z","updated_at":"2025-10-21T04:53:45.590Z","avatar_url":"https://github.com/sirwart.png","language":"Rust","funding_links":[],"categories":["Rust"],"sub_categories":[],"readme":"# ripsecrets\n\n![ripsecrets logo, a gravestone that says \"R.I.P. Secrets ?-20XX Death by Exposure\"](.github/ripsecrets-logo.svg)\n\n`ripsecrets` is a command-line tool to prevent committing secret keys into your source code. `ripsecrets` has a few features that distinguish it from other secret scanning tools:\n\n## What makes ripsecrets different\n\n`ripsecrets` has a few features that distinguish it from other secret scanning tools:\n\n1. **Focused on pre-commit**. It's a lot cheaper to prevent secrets from getting committed in the first place than dealing with the consequences once a secret that has been committed to your repository has been detected.\n\n2. **Extremely fast**. Using a secret scanner shouldn't slow down your development workflow, so `ripsecrets` is 95 times faster or more than other tools. [Learn more about how it's designed for performance](#performance).\n\n3. **Always local operation**. Many other secret scanners try to verify that the secrets are valid, which in practice means sending strings from your source code to 3rd party services automatically. There's a security versus convenience tradeoff in that decision, but `ripsecrets` is designed to be the best \"local only\" tool and will never send data off of your computer.\n\n4. **Low rate of false positives**. While local-only tools are always going to have more false positives than one that verifies secrets, `ripsecrets` uses a probability theory based approach in order to detect keys more accurately than other tools.\n\n5. **Single binary with no dependencies**. Installing `ripsecrets` is as easy as copying the binary into your `bin` directory.\n\n## Usage\n\nBy default, running `ripsecrets` will recursively search source files in your current directory for secrets.\n\n```sh\nripsecrets\n```\n\nFor every secret it finds, it will print out the file, line number, and the secret that was found. If it finds any secrets, it will exit with a non-zero status code.\n\nYou can optionally pass a list of files and directories to search as arguments.\n\n```sh\nripsecrets file1 file2 dir1\n```\n\nThis is most commonly used to search files that are about to be committed to source control for accidentally included secrets.\n\n### Installing ripsecrets as a pre-commit hook\n\nYou can install `ripsecrets` as a pre-commit hook _automatically_ in your current git repository using the following command:\n\n```sh\nripsecrets --install-pre-commit\n```\n\nIf you would like to install `ripsecrets` _manually_, you can add the following command to your `pre-commit` script:\n\n```sh\nripsecrets --strict-ignore `git diff --cached --name-only --diff-filter=ACM`\n```\n\nPassing `--strict-ignore` ensures that your `.secretsignore` file is respected when running secrets as a pre-commit.\n\n## Installation\n\n### Homebrew\n\n[`ripsecrets`](https://formulae.brew.sh/formula/ripsecrets) is available in Homebrew for macOS and Linux:\n\n```sh\nbrew install ripsecrets\n```\n\n### Pre-built\n\nYou can download a prebuilt binary for the latest release from the [releases](https://github.com/sirwart/ripsecrets/releases) page.\n\n### Cargo\n\nAlternatively, if you have [Rust](https://www.rust-lang.org/tools/install) and Cargo installed, you can run:\n\n```sh\ncargo install --git https://github.com/sirwart/ripsecrets --branch main\n```\n\n### Nix Flake\n\nAssuming you have enabled [Flakes](https://nixos.wiki/wiki/Flakes) in your Nix configuration, you can build the `ripsecrets` binary and make it available in your default Nix profile by running:\n\n```sh\nnix profile install github:sirwart/ripsecrets\n```\n\n### Using `pre-commit`\n\n`ripsecrets` works as a hook for [the pre-commit framework](https://pre-commit.com/).\nAdd the following to your `.pre-commit-config.yaml` file:\n\n```yaml\nrepos:\n  - repo: https://github.com/sirwart/ripsecrets\n    rev: v0.1.8 # Use latest tag on GitHub\n    hooks:\n      - id: ripsecrets\n        # uncomment to check additional patterns\n        # args:\n        # - --additional-pattern 'mytoken*'\n        # - --additional-pattern 'mykey*'\n```\n\nThere are two hooks available:\n\n- `ripsecrets` (Recommended)\n\n  pre-commit will set up a Rust environment from scratch to compile and run ripsecrets.\n  See the [pre-commit rust plugin docs](https://pre-commit.com/#rust) for more information.\n\n- `ripsecrets-system`\n\n  pre-commit will look for `ripsecrets` on your `PATH`.\n  This hook requires you to install ripsecrets separately, e.g., with your package manager or [a prebuilt binary release](https://github.com/sirwart/ripsecrets/releases).\n  It is only recommended if you are happy making all repository users install `ripsecrets` manually.\n\n## Ignoring secrets\n\n`ripsecrets` will respect your .gitignore files by default, but there might still be files you want to exclude from being scanned for secrets. To do that, you can create a .secretsignore file, which supports similar syntax to a .gitignore file for ignoring files. In addition to excluding files, it also supports a `[secrets]` section that allows ignoring individual secrets.\n\n```sh\ntest/*\ndummy\n\n[secrets]\npAznMW3DsrnVJ5TDWwBVCA\n```\n\nIn addition to the .secretsignore file, `ripsecrets` is compatible with `detect-secrets` style allowlist comments on the same line as the detected secret:\n\n```sh\ntest_secret = \"pAznMW3DsrnVJ5TDWwBVCA\" # pragma: allowlist secret\n```\n\n## Finding custom secrets\n\nIn some cases, you may have a custom secret that's not recognized by `ripsecrets`. To detect these, call `ripsecrets` with the `--additional-pattern` argument:\n\n```sh\nripsecrets --additional-pattern my-secret-\\*\n```\n\nAny capturing groups in the regex will be tested for randomness before being reported as a secret. If you do not want this behavior, use non-capturing groups in your regex. For example instead of `(foo|bar)` use `(?:foo|bar)`.\n\nIf the secret pattern you're trying to detect is a publicly documented secret pattern, please open [an issue](https://github.com/sirwart/ripsecrets/issues/new).\n\n## How it works\n\n`ripsecrets` has 2 types of secrets that it can find in code:\n\n1. Secrets with known patterns that can be matched. API keys from services like Stripe and Slack have a predefined prefix that identifies them as API keys and can be found via regular expressions very reliably. You can see the current list of known secrets matched by `ripsecrets` [here](https://github.com/sirwart/ripsecrets/blob/main/src/lib.rs#L22).\n\n2. Random strings assigned to secret variables. Some secrets, like AWS's secret access keys, don't have a known pattern that can be unambiguously matched. To detect these, `ripsecrets` looks for variables or properties that are being assigned with words like \"token\", \"secret\", and \"password\", and checks if a random string is assigned to it.\n\nTo determine if a string is random or not `ripsecrets` looks at a few properties of a string, like how many distinct characters it has, and calculates how likely it is to have occurred by random chance. If the probability that it happened by chance is less than 1 in 10,000 then it's determined to not be a secret. You can learn more about how the probability is calculated [here](https://github.com/sirwart/ripsecrets/blob/main/src/matcher/p_random.rs#L7).\n\nIf you find either a false negative (a secret that wasn't found by `ripsecrets`) or a false positive (a non-secret that was flagged as such), please open an issue or a pull request.\n\n## Performance\n\nThe slowest part of secret scanning is looking for potential secrets in a large number of files. To do this quickly, `ripsecrets` does a couple of things:\n\n1. All the secret patterns are compiled into a single regex, so each file only needs to be processed once.\n\n2. This regex is fed to [ripgrep](https://github.com/BurntSushi/ripgrep), which is specially optimized for running a regex against a large number of files quickly.\n\nAdditionally, `ripsecrets` is written in Rust, which means there's no interpreter startup time. To compare real-world performance, here's the runtime of a few different scanning tools to search for secrets in the [Sentry repo](https://github.com/getsentry/sentry) on an M1 air laptop:\n\n| tool           | avg. runtime | vs. baseline |\n| -------------- | ------------ | ------------ |\n| ripsecrets     | 0.32s        | 1x           |\n| trufflehog     | 31.2s        | 95x          |\n| detect-secrets | 73.5s        | 226x         |\n\nMost of the time, your pre-commit will be running on a small number of files, so the runtimes above are not typical, but when working with large commits that touch a lot of files, the runtime can become noticeable.\n\n## Running benchmarks\n\n```sh\ncargo bench\n```\n\nThe results will then be viewable at `target/criterion/report/index.html`.\n\n## Alternative tools\n\nEven if `ripsecrets` is not the right tool for you, if you're working on a service that deals with user data you should strongly consider using a secret scanner. Here are some alternative tools worth considering:\n\n- [detect-secrets](https://github.com/Yelp/detect-secrets)\n- [trufflehog](https://github.com/trufflesecurity/trufflehog)\n- [gitleaks](https://github.com/zricethezav/gitleaks)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsirwart%2Fripsecrets","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsirwart%2Fripsecrets","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsirwart%2Fripsecrets/lists"}